US2021232682A1PendingUtilityA1

Malware protection for virtual machines

Assignee: RUBRIK INCPriority: Jan 28, 2020Filed: Jan 28, 2020Published: Jul 29, 2021
Est. expiryJan 28, 2040(~13.5 yrs left)· nominal 20-yr term from priority
G06F 11/1451G06F 11/1469G06F 2201/84G06F 11/1461G06F 2201/81G06F 11/1464G06F 11/1484G06F 2009/45587G06F 2009/45575G06F 9/45558G06F 21/566G06F 21/564G06F 9/542G06F 21/53G06F 11/0772G06F 11/076
40
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A computer-implemented method at a data management system comprises receiving a write made to a virtual machine; computing, outside of the virtual machine, a fingerprint of the write; comparing, outside of the virtual machine, the computed fingerprint to malware fingerprints in a malware catalog; repeating the computing and comparing; and disabling the virtual machine if malware is detected based on a number of matches from the comparing breaching a predetermined threshold over a predetermined amount of time.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A data management system, comprising:
 a storage appliance configured to store a snapshot of a virtual machine;   one or more processors in communication with the storage appliance, the one or more processors configured to perform operations including:
 receiving a write made to the virtual machine; 
 computing, outside of the virtual machine, a fingerprint of the write; 
 comparing, outside of the virtual machine, the computed fingerprint to malware fingerprints in a malware catalog; 
 repeating the computing and comparing; and 
 disabling the virtual machine if malware is detected based on a number of matches from the comparing breaching a predetermined threshold over a predetermined amount of time. 
   
     
     
         2 . The system of  claim 1 , wherein the operations further include restoring the virtual machine using the snapshot stored in the storage appliance to a state before the predetermined threshold was breached. 
     
     
         3 . The system of  claim 1 , wherein the operations further include transmitting a warning to a user of the virtual machine. 
     
     
         4 . The system of  claim 1 , wherein the operations further include generating the malware catalog including generating fingerprints of binaries and compressed binaries of known malware. 
     
     
         5 . The system of  claim 1 , wherein the operations further include repeatedly generating snapshots of the virtual machine over time. 
     
     
         6 . The system of  claim 1 , wherein the operations are performed in a device that is not hosting the virtual machine. 
     
     
         7 . The system of  claim 1 , wherein the disabling determines if malware is present based on whether a number of matches from the comparing exceeds a predetermined threshold over a predetermined amount of time. 
     
     
         8 . A computer-implemented method at a data management system, the method comprising:
 receiving a write made to a virtual machine;   computing, outside of the virtual machine, a fingerprint of the write;   comparing, outside of the virtual machine, the computed fingerprint to malware fingerprints in a malware catalog;   repeating the computing and comparing; and   disabling the virtual machine if malware is detected based on a number of matches from the comparing breaching a predetermined threshold over a predetermined amount of time.   
     
     
         9 . The method of  claim 8 , further comprising restoring the virtual machine using a snapshot stored in a storage appliance to a state before the predetermined threshold was breached. 
     
     
         10 . The method of  claim 8 , further comprising transmitting a warning to a user of the virtual machine. 
     
     
         11 . The method of  claim 8 , further comprising generating the malware catalog including generating fingerprints of binaries and compressed binaries of known malware. 
     
     
         12 . The method of  claim 8 , further comprising repeatedly generating snapshots of the virtual machine over time. 
     
     
         13 . The method of  claim 8 , wherein the method performed in a device that is not hosting the virtual machine. 
     
     
         14 . The method of  claim 8 , wherein the disabling determines if malware is present based on whether a number of matches from the comparing exceeds a predetermined threshold over a predetermined amount of time. 
     
     
         15 . A non-transitory, machine-readable medium storing instructions which, when read by a machine, cause the machine to perform operations comprising, at least:
 receiving a write made to a virtual machine;   computing, outside of the virtual machine, a fingerprint of the write;   comparing, outside of the virtual machine, the computed fingerprint to malware fingerprints in a malware catalog;   repeating the computing and comparing; and   disabling the virtual machine if malware is detected based on a number of matches from the comparing breaching a predetermined threshold over a predetermined amount of time.   
     
     
         16 . The machine-readable medium of  claim 15 , wherein the operations further include restoring the virtual machine using a snapshot stored in a storage appliance to a state before the predetermined threshold was breached. 
     
     
         17 . The machine-readable medium of  claim 15 , wherein the operations further include transmitting a warning to a user of the virtual machine. 
     
     
         18 . The machine-readable medium of  claim 15 , wherein the operations further include generating the malware catalog including generating fingerprints of binaries and compressed binaries of known malware. 
     
     
         19 . The machine-readable medium of  claim 15 , wherein the operations further include repeatedly generating snapshots of the virtual machine over time. 
     
     
         20 . The machine-readable medium of  claim 15 , wherein the operations are performed in a device that is not hosting the virtual machine. 
     
     
         21 . The machine-readable medium of  claim 15 , wherein the disabling determines if malware is present based on whether a number of matches from the comparing exceeds a predetermined threshold over a predetermined amount of time.

Join the waitlist — get patent alerts

Track US2021232682A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.